Firefox before 1.0.1 allows remote attackers to spoof the (1) security and (2) download modal dialog boxes, which could be used to trick users into executing script or downloading and executing a file, aka "Firespoofing."
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10039
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100042
https://exchange.xforce.ibmcloud.com/vulnerabilities/18864
https://bugzilla.mozilla.org/show_bug.cgi?id=260560
http://www.securityfocus.com/bid/12234
http://www.redhat.com/support/errata/RHSA-2005-384.html
http://www.redhat.com/support/errata/RHSA-2005-176.html
http://www.mozilla.org/security/announce/mfsa2005-16.html
http://www.mikx.de/index.php?p=7
http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml
http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml